1 results (0.003 seconds)
CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 2

CVE-2024-54369 – WordPress Zita Site Builder plugin <= 1.0.2 - Arbitrary Plugin Installation and Activation vulnerability
https://notcve.org/view.php?id=CVE-2024-54369
11 Dec 2024 — Missing Authorization vulnerability in ThemeHunk Zita Site Builder allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Zita Site Builder: from n/a through 1.0.2. The Zita Site Builder plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capability check on one of its functions in versions up to, and including, 1.0.2. This makes it possible for unauthenticated attackers to install and activate arbitrary plugins. • https://github.com/RandomRobbieBF/CVE-2024-54369 • CWE-862: Missing Authorization •